Skip to content

fix: enforce CEK algorithm binding on Kms+Context decrypts - #204

Open
akareddy04 wants to merge 8 commits into
mainfrom
aniravk/enforce-cek-alg-binding-on-decrypt
Open

fix: enforce CEK algorithm binding on Kms+Context decrypts #204
akareddy04 wants to merge 8 commits into
mainfrom
aniravk/enforce-cek-alg-binding-on-decrypt

Conversation

@akareddy04

Copy link
Copy Markdown

Issue #, if available:

Description of changes:

When decrypting using Kms+Context mode, the KmsKeyring MUST validate that the content encryption algorithm in the KMS-authenticated encryption context matches the algorithm suite selected for decryption.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

- Add CONTENT_CIPHER_TO_ALGORITHM_SUITE and reverse map as single source of truth
- KmsKeyring CEK-alg binding check uses the reverse map; fail closed when no suite
- Restrict V3 (key-committing) binding tests to improved clients; V2 runs on all
- Strip all V3-only headers when tampering V3->V2 CBC so the binding check is the sole defense
- Fix default-enc-ctx test to use a realistic stored aws:x-amz-cek-alg
- Bump specification submodule to CEK-alg binding requirement
@akareddy04
akareddy04 requested a review from kessplas September 8, 2026 19:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant